Junglewise Threat Intelligence

CVE-2026-83291: Oracle Business Intelligence Enterprise Edition privilege escalation in Platform Security

CVE-2026-83291 · Severity: high · CVSS 7.8 · Published 2026-09-15

Technologies: Oracle Business Intelligence Enterprise Edition. Vendors: Oracle.

Executive brief

Oracle Business Intelligence Enterprise Edition is an analytics platform used to analyze and visualize business data. A local privilege escalation vulnerability allows a low-privileged user with infrastructure access to gain complete control of the platform, potentially compromising all stored analytics data, reports, and business intelligence assets.

Technical details

This is a local privilege escalation vulnerability in the Platform Security component of Oracle Business Intelligence Enterprise Edition. The vulnerability requires local logon access to the infrastructure where OBIE executes and allows a low-privileged attacker to escalate privileges without user interaction. Successful exploitation results in complete takeover of the OBIE system, with impacts to confidentiality, integrity, and availability. The vulnerability affects OBIE versions 8.2.0.0.0 and 26.01.0.0.0; patches are expected from Oracle's security advisory process.

Affected products

  • Oracle Business Intelligence Enterprise Edition 8.2.0.0.0, 26.01.0.0.0

Timeline

  • 2026-09-15: disclosed

References

Related threats